Senior SOC Engineer

Telstar

Terrassa

On-site

EUR 70,000 - 110,000

Full time

8 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Syntegon Telstar S.R.U, located in Terrassa (Barcelona), seeks a Senior SOC Engineer to own the engineering backlog across SIEM, SOAR, EDR/XDR, and log pipelines. You’ll design high-fidelity detections, build automated response workflows, and scale data infrastructure to empower analysts in incident response.

You will act as Tier 3 escalation, mentor junior analysts, and collaborate with IT, Cloud, Network, and Identity teams to strengthen log coverage and detection coverage across platforms.

Qualifications

  • 5–8+ years in cybersecurity with 3+ years in a SOC engineering, detection engineering, or senior analyst role.
  • Hands-on expertise with SIEM platforms including query authoring and detection rule development.
  • Proven experience building SOAR playbooks and automating security workflows.
  • Strong knowledge of attacker TTPs and the MITRE ATT&CK framework, with the ability to translate them into detection logic.
  • Experience with log onboarding, data normalisation, and pipeline management at scale.
  • Solid understanding of EDR/XDR, NDR, cloud telemetry, and identity signals.
  • Scripting or development skills (e.g., Python, PowerShell, KQL) for automation and tooling integration.
  • Clear written and verbal communication with the ability to document technical content for varied audiences.

Responsibilities

  • Design, develop, and maintain detection content across SIEM, EDR/XDR, and NDR platforms, aligned to MITRE ATT&CK TTPs.
  • Build and optimise SOAR playbooks and automated response workflows across triage, enrichment, containment, and evidence collection.
  • Own the onboarding of new log sources and manage data ingestion pipelines for cost-effectiveness, completeness, and reliability.
  • Act as Tier 3 technical escalation for complex investigations and high-severity incidents, supporting forensic analysis and root cause determination.
  • Maintain health, performance, and reliability of core SOC platforms and evaluate new tooling.
  • Partner with IT, Cloud, Network, and Identity teams to improve log coverage and response integration, and mentor analysts.
  • Ensure detection and engineering controls support compliance and maintain audit-ready documentation.

Skills

SOC engineering
SIEM mastery
SOAR automation
MITRE ATT&CK
Log onboarding
EDR/XDR/NDR
Scripting (Python/PowerShell/KQL)
Documentation

Tools

Python
PowerShell
KQL

Job description

Syntegon Telstar S.R.U is a company belonging to the Syntegon Group, which operates worldwide with 7,300 colleagues at 49 locations in over 20 countries.is a company belonging to the Syntegon Group, which operates worldwide.

As a brand specialising in the development of GMP consulting, engineering, construction and integrated process equipment projects, we serve companies linked to the life sciences market (pharmaceutical and biotechnology, healthcare, cosmetics, veterinary and food industries), as well as hospitals, laboratories and research centres. We also offer solutions using vacuum and high vacuum technologies for traditional and high-tech industries in the energy and aerospace sectors, as well as scientific experimentation.

Qué quedes esperar:

We are looking for a hands-on Senior SOC Engineer to join our team at our offices in Terrassa (Barcelona) to help design, build, and continuously improve the technology that powers our Security Operations Center. In this role, you’ll own the engineering backlog across SIEM, SOAR, EDR/XDR, and log pipelines—developing high-fidelity detections, efficient workflows, and resilient security data infrastructure.

Working closely with the SOC Leader and analyst teams, you’ll serve as a technical escalation point for complex incidents and help strengthen the SOC through automation, process improvement, and reliable engineering solutions. The ideal candidate combines strong security engineering expertise with a practical, collaborative approach and a passion for enabling analysts to respond more effectively.

Key Responsibilities
  • Design, develop, and maintain detection content across SIEM, EDR/XDR, and NDR platforms, aligned to MITRE ATT&CK TTPs, owning the full use case lifecycle from requirements through to tuning and deprecation.
  • Build and optimise SOAR playbooks and automated response workflows, identifying and implementing automation opportunities across triage, enrichment, containment, and evidence collection.
  • Own the onboarding of new log sources and manage data ingestion pipelines for cost-effectiveness, completeness, and reliability.
  • Act as Tier 3 technical escalation for complex investigations and high-severity incidents, supporting forensic analysis, malware triage, and root cause determination.
  • Maintain the health, performance, and reliability of core SOC platforms and evaluate new tooling aligned to the SOC's maturity roadmap.
  • Partner with IT, Cloud, Network, and Identity teams to improve log coverage and response integration, and mentor Tier 1–2 analysts on detection logic and tooling.
  • Ensure detection and engineering controls support relevant compliance requirements and maintain audit-ready documentation across platforms and pipelines.
Qué aportarás:
Required Qualifications:
  • 5–8+ years in cybersecurity with 3+ years in a SOC engineering, detection engineering, or senior analyst role.
  • Deep hands-on expertise with SIEM platforms including query authoring and detection rule development.
  • Proven experience building SOAR playbooks and automating security workflows.
  • Strong knowledge of attacker TTPs and the MITRE ATT&CK framework, with the ability to translate them into detection logic.
  • Experience with log onboarding, data normalisation, and pipeline management at scale.
  • Solid understanding of EDR/XDR, NDR, cloud telemetry, and identity signals.
  • Scripting or development skills (e.g., Python, PowerShell, KQL) for automation and tooling integration.
  • Clear written and verbal communication with the ability to document technical content for varied audiences.
Preferred Qualifications:
  • Certifications: GIAC (GCIA, GCED, GCIH, GCFA, GMON), Microsoft SC-200, or equivalent cloud security certifications.
  • Experience with threat hunting methodologies and proactive adversary detection.
  • Exposure to offensive security, red teaming, or purple team exercises.
  • Experience in OT/ICS security environments (if relevant to the business).
  • Familiarity with data privacy, eDiscovery, and chain-of-custody requirements during investigations.
Información adicional

Availability to travel (approximately 10–20%) when required (HQ in Germany).

Por Syntegon y sus subsidiarias, la diversidad es una preocupación clave. Exclusivamente promovemos un ambiente donde todos los empleados, independientemente de su género, edad, origen, religión, orientación sexual, identidad de género o necesidades especiales, sean tratados de manera equitativa. Si esta oferta de trabajo utiliza únicamente la forma masculina, es por razones de legibilidad y se refiere a individuos de todos los géneros.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Telstar • Terrassa

On-site
EUR 70,000 - 110,000
Senior SOC Analyst
Senior SOC Analyst

Syntegon Technology GmbH • Terrassa

On-site
EUR 54,000 - 76,000
Senior SOC Engineer
Senior SOC Engineer

SmartRecruiters, Inc. • Terrassa

On-site
EUR 65,000 - 90,000
Senior SOC Analyst
Senior SOC Analyst

SmartRecruiters, Inc. • Terrassa

On-site
EUR 55,000 - 75,000
Cibersecurity Automation Engineer SOC SIEM/SOAR (F/M)
Cibersecurity Automation Engineer SOC SIEM/SOAR (F/M)

T-Systems Iberia • Madrid

On-site
EUR 40,000 - 60,000
Ambiente de trabajo internacional y positivo
Modelo de trabajo híbrido
Horario flexible
+4
Senior SOC Engineer – SIEM, SOAR & Detection Automation
Senior SOC Engineer – SIEM, SOAR & Detection Automation

SmartRecruiters, Inc. • Terrassa

On-site
EUR 65,000 - 90,000
SOC Analyst
SOC Analyst

SOTEC CONSULTING • Barcelona

On-site
EUR 30,000 - 40,000
Analista SOC (EDR) – Barcelona, España
Analista SOC (EDR) – Barcelona, España

Sotec Consulting • Barcelona

Hybrid
EUR 32,000 - 46,000
Proyectos innovadores
Crecimiento profesional
Formación continua
+1
SOC Manager
SOC Manager

Empresa Confidencial • País Vasco

On-site
EUR 45,000 - 65,000
Beneficios adicionales a concretar
Senior Cibersecurity Incident Responder (híbrido-2 días en SANT CUGAT -Barcelona)
Senior Cibersecurity Incident Responder (híbrido-2 días en SANT CUGAT -Barcelona)

knowmad mood • Las Rozas de Madrid

On-site
EUR 55,000 - 90,000
Contrato indefinido
Modelo híbrido
Horario flexible
+9